ACCESS-DEF · Question #25
When a user enrolls a mobile device (iOS or Android) without enabling mobile device management, what happens? (Choose three.)
The correct answer is A. The device is added to the Endpoints page in the Admin and User portals. Note: The question asks for three correct answers; based on CyberArk Identity behavior, the full correct set is A, B, and F. The prompt appears to list only A, but the explanation below covers all three. Enrolling a device without MDM gives CyberArk Identity basic visibility…
Question
Options
- AThe device is added to the Endpoints page in the Admin and User portals.
- BThe web applications assigned to the user are added to the Web Apps screen in the CyberArk Identity mobile app.
- CThe associated mobile applications are added and available for deployment automatically.
- DThe mobile device policies defined in the CyberArk Cloud Directory policy service policy set are installed.
- EThe device's model name, serial number, OS number, and Network Carrier information will be uploaded to the Identity portal.
- FThe mobile phone can now be used as a MFA Authentication Factor.
How the community answered
(47 responses)- A89% (42)
- C6% (3)
- E2% (1)
- F2% (1)
Explanation
Note: The question asks for three correct answers; based on CyberArk Identity behavior, the full correct set is A, B, and F. The prompt appears to list only A, but the explanation below covers all three.
Enrolling a device without MDM gives CyberArk Identity basic visibility and authentication capability, but no management control. A is correct because any enrollment-MDM or not-registers the device in the Endpoints page so administrators can track it. B is correct because the user's assigned web apps populate the Web Apps screen in the CyberArk Identity mobile app regardless of MDM status; this is purely an app-portal function. F is correct because once a device is enrolled, the mobile app can generate OTPs or push notifications for MFA, which requires no management profile.
The distractors are wrong because they all describe MDM-specific capabilities: C (automatic mobile app deployment) and D (policy installation) require an MDM profile to push configurations to the device, and E (harvesting hardware details like serial number and carrier) also requires MDM-level device access.
Memory tip: Think "No MDM = No Management." Without MDM, CyberArk can only see the device (Endpoints page), serve the user (web apps in the mobile app), and verify identity (MFA)-the three S's: See, Serve, Secure. Anything that installs, deploys, or collects hardware data needs MDM.
Topics
Community Discussion
No community discussion yet for this question.